THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

4 min read

AI-assisted briefingHow we put it together ↗

AT A GLANCE

  • Check Point reports exploitation of its Management Server flaw dating back to July 23, 2026, and has released emergency fixes.
  • The F5 BIG-IP APM flaw is listed in CISA’s Known Exploited Vulnerabilities catalog; exposure requires both an APM access policy and an OAuth profile on a virtual server.
  • WordPress 7.1.2 fixes an unauthenticated flaw affecting releases 4.7.0 through 7.1.1; server-side code execution depends on server and theme conditions.
01

Check Point reports exploitation of management-server flaw; F5 APM attacks also reported

Check Point issued emergency fixes for CVE-2026-93616, which the company says had been exploited since at least July 23, 2026. It also said attackers began probing a separate pre-authentication remote-code-execution flaw in Quantum Security Gateway shortly after patches were released on September 9. The report’s headline also references attacks on F5 BIG-IP APM, but its available content provides no details on those attacks.

What changed For the separate Quantum Security Gateway flaw, patches released on September 9 were followed by probing within days; the excerpt does not establish successful exploitation.

Why it matters Management Server operators face an incident-response question as well as a patching task: exploitation dating back to July 23 gives them reason to assess historical exposure.

HelpNet Security ↗
02

CISA adds critical F5 BIG-IP APM flaw to Known Exploited Vulnerabilities catalog

Rapid7 reports that CVE-2026-94127 is a critical, unauthenticated heap-based buffer overflow that may allow remote code execution on affected BIG-IP APM virtual servers. Exposure requires both an APM access policy and an OAuth profile on the virtual server; Rapid7 says the flaw was added to CISA’s Known Exploited Vulnerabilities catalog on September 22, while no public proof of concept had been confirmed. F5 lists hotfixes for affected release trains, and Rapid7 says F5 offers an iRule workaround through its support team.

Why it matters Exposure triage should distinguish configured virtual servers from BIG-IP deployments generally: the vulnerable combination can put edge-facing access-control infrastructure at risk, while the reported flaw does not expose the control plane.

What to watch next Rapid7 said vulnerability checks were expected in its September 23 content release. Their delivery remains unconfirmed in the supplied report.

Rapid7 ↗
03

WordPress 7.1.2 patches critical unauthenticated path-traversal flaw

WordPress version 7.1.2 fixes CVE-2026-87902, which the project describes as an unauthenticated vulnerability that can make WordPress load an attacker-selected PHP file from outside the active theme folders. Under certain server and theme conditions, the flaw can lead to code execution on the server. Releases from 4.7.0 through 7.1.1 are listed as affected.

What changed Version 7.1.2 supplies a fix for a flaw spanning releases 4.7.0 through 7.1.1, making this relevant to older installations as well as the preceding release.

Why it matters For site operators, the potential consequence extends beyond loading an unintended file to server-side code execution, although that outcome depends on the server and active theme.

HelpNet Security ↗
04

Microsoft-led coalition disrupts EvilTokens phishing service tied to more than 12,000 inboxes

Microsoft says a law-enforcement and private-sector coalition disrupted the EvilTokens phishing service, which it attributes to compromises of more than 12,000 inboxes at over 10,000 organizations. With authorization from a U.S. district court, Microsoft and Health-ISAC worked with several partners to seize 50 websites and disable more than 150 associated domains.

What changed The coalition moved against the service’s operating infrastructure through court-authorized website seizures and domain disabling.

Why it matters The intervention targets infrastructure supporting compromises across thousands of organizations, giving it broader reach than removing an individual phishing lure.

HelpNet Security ↗
05

Researcher details unauthenticated heap-overflow exploit in Canon MF753Cdw printer

A Zero Day Initiative researcher describes CVE-2024-0244, an unauthenticated heap-based buffer overflow in the Canon MF753Cdw that can lead to an arbitrary free. The researcher says a malformed fax payload with an oversized length field could corrupt a heap object, and details an exploitation method that uses the printer’s BJNP protocol to store shellcode at a known address. The post says the vulnerability’s precise root cause was not identified.

Why it matters MF753Cdw operators cannot assume an unplugged phone line removes the fax attack surface: the researcher’s printer accepted fax requests through its HTTP interface without one.

What to watch next The precise cause of the overflow remains unresolved in the write-up; the proposed fax-related heap object is an assumption rather than an identified implementation.

ZeroDayInitiative ↗
06

DarkMe malware campaign switches to phishing emails instead of zero-day exploits

Huntress has spotted DarkMe, a remote access trojan and information stealer previously associated with targeting financial-market traders and cryptocurrency users, being distributed through a simpler approach. The attackers are using email to persuade recipients to run the malware rather than relying on zero-day exploits, according to Help Net Security’s report.

What changed The observed distribution relies on recipients running malware from an email rather than on zero-day exploitation. This is a change in the reported delivery chain, not proof of a permanent shift across all campaigns.

Why it matters Recipients persuaded to run the payload face both remote-access and information-theft risks; the email is a route to malware execution, not merely a credential lure.

HelpNet Security ↗
Cybersecurity — September 24, 2026 | Briefing24